CVE-2026-75059Medium· 4.4▾ SunlitIn JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
pycharm < 2026.2.1Upgrade past the affected range:
pycharm 2026.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75060High· 8.4In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
CVE-2026-86491Low· 3.5In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
CVE-2026-86484Medium· 4.6In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
CVE-2026-86483Medium· 5.4In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-75048High· 8.2In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVE-2026-63077Critical· 9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol